Improper Authorization in Moodle - CVE-2020-25629
Published: September 21, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote user to escalate privileges within the application.
The vulnerability exists due to an error within the "Log in as" feature. A remote user with "Log in as" capability in a course context (typically, course managers) can gain access to some site administration capabilities by "logging in as" a System manager.